rootpwn

medium · CVSS v3 5.4 · CVSS v4 5.3

CVE-2026-92778

CMAK versions through 3.0.0.6 fail to enforce the scheduled leader election feature toggle on HTML form routes. This allows users with web i

Overview

CMAK versions through 3.0.0.6 fail to enforce the scheduled leader election feature toggle on HTML form routes. This allows users with web interface access to bypass the feature gate and interact directly with the form endpoints. Consequently, unauthorized actors can start or stop the recurring election scheduler, potentially disrupting leadership across managed Kafka clusters.

Description

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election scheduler, disrupting leadership across managed Kafka clusters.

Impact

Impacts Kafka cluster management availability and operational integrity. Confidentiality is unaffected, integrity is slightly impacted by unauthorized management state changes, and availability is moderately impacted due to forced changes in cluster leadership scheduling.

Remediation

Update CMAK to a fixed release beyond version 3.0.0.6 when available. As a workaround, restrict network access to the CMAK management console using firewalls, VPNs, or strict reverse-proxy access controls to ensure only authorized personnel can reach the web interface.

Risk context

Presents a medium severity level (CVSS v3: 5.4, CVSS v4: 5.3) with no EPSS score reported. The vulnerability requires network access to the management console and poses a moderate threat to operational stability rather than data exposure.

Affected products

  • CMAK
  • Yahoo Kafka Manager

Scores

Severity
medium
CVSS v2
5.5
CVSS v3
5.4
CVSS v4
5.3
EPSS

CMAK Apache Kafka Access Control Feature Toggle Availability CVE-2026-92778

← All CVEs